HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
University of the People
bd_1d855dd1d17c87fb · schema v1 · pii pii-v1
Full breach record for University of the People →University of the People notified the California AG of a data breach where unauthorized third parties accessed and potentially exfiltrated files from its SharePoint platform between January 2 and January 10, 2022. The university learned of the incident in mid-January 2022. Affected data may include personal information such as names, addresses, and potentially Social Security numbers. The university engaged third-party experts, secured its network, and offered one year of credit monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_ac9b991feced758eMaine State AGfiled 2023-04-05Verified
- bd_57d53b879077ad26Vermont State AGfiled 2023-04-04(1d gap)Verified
- bd_7684067d9ceb71f9Montana State AGfiled 2023-04-04(1d gap)Candidate
- bd_970e1ff5835dd356New Hampshire State AGfiled 2023-04-04(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565156
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2023
- Raw hash
- 0b7da2e787b5db27e28ef8c48e96e83f81e4d359a9ff2476806495f66877efcf
Reporting entity
- Name
- University of the Peoplenorm: university of the people
Victim entity
- Name
- University of the Peoplenorm: university of the people
Incident
- Discovered
- Jan 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 15 months(445 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.